امنیت سایبری SOC
327 subscribers
160 photos
10 videos
169 files
212 links
Information about soc , cyber security defence and cyber security news
Download Telegram
سرویس اطلاع رسانی نقض داده Have I Been Pwned (HIBP) تعداد ۲۸۴,۱۳۲,۹۶۹ حساب کاربری که توسط بدافزارهای Infostealer دزدیده و در کانال تلگرامی ALIEN TXTBASE پیدا شدن رو به دیتابیس خودش اضافه کرده.

حجم این داده ها، 1.5 ترابایت و شامل ۲۳ میلیارد ردیف است که ۴۹۳ میلیون جفت سایت و آدرس ایمیل منحصربه‌فرد رو در بر میگیره و ۲۸۴ میلیون آدرس ایمیل منحصربه‌فرد رو تحت تأثیر قرار داده.

با توجه به تعداد زیاد اکانتها در این مجموعه، احتمالاً این داده‌ها شامل اعتبارنامه‌های قدیمی و جدید است که از طریق حملات Credential Stuffing و نقضهای داده‌ای، دزدیده شدن.

قبل از اضافه کردن این اکانتها به HIBP، با بررسی اینکه آیا تلاش برای بازنشانی رمز عبور با استفاده از آدرسهای ایمیل دزدیده‌ شده باعث میشه سرویس ایمیل بازنشانی رمز عبور رو ارسال کنه یا نه، صحت اونارو تأیید کردن.

همچنین این سرویس یسری API هم به سایتش اضافه کرده که امکان جستجو رو برای صاحبان سایتها فراهم میکنه.

برای اینکه بدونید، آیا تحت تاثیر این نقض بودید، فقط کافیه وارد سایت HIBP بشید و ایمیلتون رو برای جستجو وارد کنید.

اگه بخوایید بدونید که اطلاعات اکانتتون در کدوم سایتها تحت تاثیر بوده، باید اشتراک تهیه کنید. این کار برای جلوگیری از افشای اطلاعات حساس انجام دادن.
👍1
ClickFix Phishing Campaign Deploying Havoc C2 via Microsoft SharePoint

ClickFix phishing attack is tricking users into executing malicious PowerShell commands, leading to the deployment of Havoc C2, a post-exploitation framework similar to Cobalt Strike. Attackers distribute phishing emails containing HTML attachments with fake OneDrive error messages, prompting users to run PowerShell scripts. These scripts retrieve payloads from compromised Microsoft SharePoint sites, conduct sandbox checks, modify Windows Registry, install Python if missing, and ultimately inject Havoc C2 as a DLL. The malware leverages Microsoft Graph API to disguise C2 communications, making detection difficult. Mitigation: Avoid executing unsolicited scripts, verify email sources, block unauthorized PowerShell execution.
امنیت سایبری SOC
ClickFix Phishing Campaign Deploying Havoc C2 via Microsoft SharePoint ClickFix phishing attack is tricking users into executing malicious PowerShell commands, leading to the deployment of Havoc C2, a post-exploitation framework similar to Cobalt Strike.…
حمله فیشینگ ClickFix کاربران را فریب می‌دهد تا دستورات مخرب PowerShell را اجرا کنند که در نهایت منجر به استقرار Havoc C2 می‌شود، یک فریمورک پس از بهره‌برداری مشابه Cobalt Strike. مهاجمان ایمیل‌های فیشینگ حاوی فایل‌های HTML ارسال می‌کنند که شامل پیام‌های خطای جعلی OneDrive هستند و کاربران را ترغیب می‌کنند تا اسکریپت‌های PowerShell را اجرا کنند.

این اسکریپت‌ها، محموله‌های مخرب را از سایت‌های آلوده Microsoft SharePoint دریافت کرده، محیط‌های آزمایشی (sandbox) را بررسی می‌کنند، رجیستری ویندوز را تغییر می‌دهند، در صورت نبود Python آن را نصب می‌کنند و در نهایت Havoc C2 را به‌صورت DLL تزریق می‌کنند.

بدافزار از Microsoft Graph API برای پنهان کردن ارتباطات C2 استفاده می‌کند که شناسایی آن را دشوار می‌سازد.
راهکارهای مقابله:

از اجرای اسکریپت‌های ناشناس خودداری کنید.
منابع ایمیل‌ها را تأیید کنید.
اجرای PowerShell غیرمجاز را مسدود کنید.
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs

A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted on Webflow CDN, GoDaddy, and Wix, these PDFs execute PowerShell scripts when victims interact with the CAPTCHA, leading to credential theft and remote access via GhostSocks proxy malware. Mitigation: Avoid downloading untrusted PDFs, do not interact with unsolicited CAPTCHA
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
یک کمپین فیشینگ گسترده با استفاده از تصاویر جعلی CAPTCHA در فایل‌های PDF مخرب، بدافزار Lumma Stealer را توزیع می‌کند و بیش از 1,150 سازمان در آمریکای شمالی، جنوب اروپا و آسیا را هدف قرار داده است.

این PDFها که در Webflow CDN، GoDaddy و Wix میزبانی شده‌اند، هنگام تعامل قربانیان با CAPTCHA، اسکریپت‌های PowerShell را اجرا می‌کنند که منجر به سرقت اطلاعات کاربری و دسترسی از راه دور از طریق بدافزار پروکسی GhostSocks می‌شود.
راهکارهای مقابله:

از دانلود فایل‌های PDF ناشناس خودداری کنید.
با CAPTCHAهای مشکوک و ناخواسته تعامل نداشته باشید.
امنیت سایبری SOC
Lumma Stealer Malware Delivered via Fake CAPTCHA PDFs A large-scale phishing campaign is using fake CAPTCHA images in malicious PDFs to distribute Lumma Stealer malware, targeting 1,150+ organizations across North America, Southern Europe, and Asia. Hosted…
Public indicators:

https[://]booking[.]procedeed-verific[.]com/goo_pdf

https[://]payment-confirmation[.]82736[.]store/pgg46

0419A1942AF24E21F988249DB2C1748509471CCA6B5B7FE9305EAC817C5C4D41

64C9723E61808E95716485B020F24CE3DADFD982E2BF3E94E7EE5E8CED388DC2

71FE618A360C3D077AF47DDB17B35DE5300C94D3F46FB173A039C01D8CA6B86C

7B3BD767FF532B3593E28085940646F145B9F32F2AE97DFA7CDD652A6494257D

8C408B29CBD76F60ECDF703F737408C5C0AE4D87BFA9C43F3307A36DF408122B

AAF43AAB8C08B41682F2B682B05D612651A2B43E235ABC06BB5C4FDE01BF50BE
Security Updates
Account Takeover Vulnerability in ADSelfService Plus (CVE-2025-1723)
The UAE Cyber Security Council has identified a high-severity vulnerability in ManageEngine ADSelfService Plus, a widely used self-service password management and single sign-on (SSO) solution. Organizations utilizing affected versions are advised to apply security updates immediately to mitigate potential risks.
Details
Vulnerability Details • CVE Identifier: CVE-2025-1723
• Severity: High
• Vulnerability Type: Improper Session Handling
• Description:
• The vulnerability arises due to improper session handling in ADSelfService Plus, potentially allowing unauthorized access to user enrollment data.
• If Multi-Factor Authentication (MFA) is not enabled for ADSelfService Plus login, attackers could exploit this flaw to access sensitive user information and potentially compromise accounts.
Affected Products and Services • ADSelfService Plus builds 6510 and earlier
Fixed Versions • ADSelfService Plus build 6511
Mitigation/Workaround • Immediate Upgrade: Update ADSelfService Plus to build 6511 or later to patch the vulnerability.
• Enforce Multi-Factor Authentication (MFA): Enable MFA for ADSelfService Plus logins to reduce the risk of unauthorized access.
• Monitor User Activity: Regularly audit access logs for signs of unauthorized login attempts or unusual user behavior.
References
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
Security Updates – Android
Google has issued the Android Security Bulletin for March 2025, addressing multiple high-risk vulnerabilities affecting Android devices. Among these, CVE-2024-43093 and CVE-2024-50302 have been confirmed as actively exploited, posing serious security threats. Organizations and users are urged to apply security updates immediately.
Details
Vulnerability Details Actively Exploited Vulnerabilities
• CVE-2024-43093 – Elevation of Privilege (EoP) in Android Framework
o Affects Google Play system updates
o Exploits a weakness in the Documents UI component
o Could allow attackers to gain elevated privileges and access sensitive user data
• CVE-2024-50302 – Kernel Memory Exposure in Linux Kernel (HID: core)
o Enables unauthorized access to kernel memory
o Exploited in real-world attacks for device compromise and spyware installation
Critical Remote Code Execution (RCE) Vulnerabilities
• CVE-2025-0074, CVE-2025-0075, CVE-2025-0084, CVE-2025-22403, CVE-2025-22408, CVE-2025-22410, CVE-2025-22411, CVE-2025-22412
o Multiple critical RCE vulnerabilities in the Android System
o Allow attackers to execute code remotely without user interaction
o Could be used for malware deployment, device takeover, and data theft
Affected Products and Services • Android 13, 14, and 15
Mitigation/Workaround • Immediate Update: Apply the latest Android security patch (March 2025 update)
• Restrict App Permissions: Minimize excessive app privileges to prevent exploitation
• Monitor Device Activity: Look for unusual behavior, slow performance, or unexpected app installations
• Enable Google Play Protect: Ensure Google Play Protect is active to detect and remove malware
References
https://source.android.com/docs/security/bulletin/2025-03-01
👍1
Malicious Code Found in VSCode Extensions

Microsoft removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ after researchers found malicious obfuscated JavaScript capable of stealing credentials. The extensions, installed 9 million+ times, were disabled across all VSCode instances.

IoCs: equinusocio.moxer-theme, equinusocio.vsc-material-theme, equinusocio.vsc-material-theme-icons, equinusocio.vsc-community-material-theme, equinusocio.moxer-icons.

Mitigation: Uninstall affected extensions, review all installed VSCode extensions for anomalies, and ensure dependencies come from trusted sources.
👍1
امنیت سایبری SOC
Malicious Code Found in VSCode Extensions Microsoft removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ after researchers found malicious obfuscated JavaScript capable of stealing credentials. The extensions,…
کد مخرب در افزونه‌های VSCode شناسایی شد

مایکروسافت دو افزونه محبوب VSCode با نام‌های "Material Theme – Free" و "Material Theme Icons – Free" را پس از شناسایی جاوا اسکریپت مخرب و مبهم‌سازی‌شده که قادر به سرقت اطلاعات کاربری بود، حذف کرد. این افزونه‌ها بیش از ۹ میلیون بار نصب شده بودند و در تمامی نسخه‌های VSCode غیرفعال شدند.
شاخص‌های نفوذ (IoCs):

equinusocio.moxer-theme
equinusocio.vsc-material-theme
equinusocio.vsc-material-theme-icons
equinusocio.vsc-community-material-theme
equinusocio.moxer-icons

راهکارهای مقابله:

افزونه‌های آلوده را حذف کنید.
تمامی افزونه‌های نصب‌شده در VSCode را برای یافتن موارد مشکوک بررسی کنید.
اطمینان حاصل کنید که وابستگی‌ها (Dependencies) از منابع معتبر دریافت شده‌اند.
👍1
Windows Disk Cleanup Privilege Escalation (CVE-2025-21420)
A high-severity vulnerability in Windows Disk Cleanup Tool (cleanmgr.exe) allows local privilege escalation (LPE) to SYSTEM via DLL sideloading. A proof-of-concept has been published on GitHub, increasing the risk of exploitation.
Mitigation: Apply the February 2025 Patch Tuesday update

Everest Forms Plugin Vulnerability (CVE-2025-1128)
A critical vulnerability has been identified in the Everest Forms WordPress plugin (versions ≤ 3.0.9.4), affecting over 100,000 sites. This flaw allows unauthenticated attackers to upload, read, and delete arbitrary files, potentially leading to full site takeover. ​
Fix: Everest Forms version 3.0.9.5 or later

GitLab XSS Vulnerabilities (CVE-2025-0475 & CVE-2025-0555): High-severity XSS flaws in GitLab CE/EE 15.10–17.9.0 allow JavaScript injection. Fix: Update to 17.9.1, 17.8.4, 17.7.6.

Cisco Nexus Switches DoS (CVE-2025-20111): Denial of Service flaw in Nexus 3100, 3200, 3400, 3600, 9200, 9300, 9400 Series (NX-OS mode).
Fixed Versions: Refer to Cisco bug IDs CSCwj98161 and CSCwk41797 for specific fixed versions.
امنیت سایبری SOC
Windows Disk Cleanup Privilege Escalation (CVE-2025-21420) A high-severity vulnerability in Windows Disk Cleanup Tool (cleanmgr.exe) allows local privilege escalation (LPE) to SYSTEM via DLL sideloading. A proof-of-concept has been published on GitHub, increasing…
### مجموعه آسیب‌پذیری‌های امنیتی جدید

#### ۱. افزایش سطح دسترسی در Windows Disk Cleanup (CVE-2025-21420)
یک آسیب‌پذیری با شدت بالا در ابزار Windows Disk Cleanup (cleanmgr.exe) امکان افزایش سطح دسترسی محلی (LPE) به SYSTEM را از طریق DLL Sideloading فراهم می‌کند. انتشار PoC در GitHub خطر بهره‌برداری را افزایش داده است.
✅ راهکار: به‌روزرسانی Patch Tuesday فوریه ۲۰۲۵ را اعمال کنید.

---
#### ۲. آسیب‌پذیری در افزونه Everest Forms (CVE-2025-1128)
یک آسیب‌پذیری بحرانی در افزونه Everest Forms برای وردپرس (نسخه‌های ≤ 3.0.9.4) شناسایی شده که بیش از ۱۰۰,۰۰۰ سایت را تحت تأثیر قرار می‌دهد. این نقص به مهاجمان غیرمجاز اجازه می‌دهد تا فایل‌های دلخواه را آپلود، خوانده و حذف کنند که می‌تواند به تسلط کامل بر سایت منجر شود.
✅ راهکار: به‌روزرسانی به نسخه Everest Forms 3.0.9.5 یا جدیدتر.

---
#### ۳. آسیب‌پذیری‌های XSS در GitLab (CVE-2025-0475 & CVE-2025-0555)
دو آسیب‌پذیری با شدت بالا از نوع XSS در GitLab CE/EE نسخه‌های 15.10 تا 17.9.0 شناسایی شده که به مهاجمان امکان تزریق جاوا اسکریپت را می‌دهد.
✅ راهکار: به‌روزرسانی به نسخه‌های 17.9.1، 17.8.4، 17.7.6.

---
#### ۴. آسیب‌پذیری DoS در سوئیچ‌های Cisco Nexus (CVE-2025-20111)
یک آسیب‌پذیری Denial of Service (DoS) در سوئیچ‌های Cisco Nexus 3100، 3200، 3400، 3600، 9200، 9300، 9400 (NX-OS mode) شناسایی شده است.
✅ راهکار: برای نسخه‌های اصلاح‌شده به Bug IDهای CSCwj98161 و CSCwk41797 در سایت سیسکو مراجعه کنید.
👍1